Data Processing Addendum
Last updated October 8, 2026
This addendum is part of the Terms of Service between RouteKeep ("processor") and the business using RouteKeep("controller"). It covers the personal data of the business's customers and staff that we process to provide the service.
Instructions
We process the data only to provide the service and as the business directs through it, and not for any other purpose.
Confidentiality and security
- Only people who need access to provide or support the service have it, and they are bound to keep it confidential.
- Each business's data is isolated by row-level security in the database, tested automatically on every change.
- Data is encrypted in transit; production data has automated daily backups and a tested restore before it holds real customer records.
- Card data never reaches our systems.
Subprocessors
The business authorizes the services on the subprocessors page. We will post changes there at least 30 days before a new subprocessor receives customer data, and the business may object by ending the agreement.
Breaches
We will tell the business without undue delay, and within 72 hours of confirming a breach affecting its data, with what we know and what we are doing about it.
Help with requests
We will help the business answer requests from its customers to see, correct or delete their information, mostly through tools in the app (edit, export).
End of service
The business can export everything at any time. After the account closes we delete the data within 30 days, except what the law requires us to keep.